Cryptology ePrint Archive: Report 2013/532

On a Relation between the Ate Pairing and the Weil Pairing for Supersingular Elliptic Curves

Takakazu Satoh

Abstract: The hyperelliptic curve Ate pairing provides an efficient way to compute a
bilinear pairing on the Jacobian variety of a hyperelliptic curve.
We prove that, for supersingular elliptic curves with embedding degree
two, square of the Ate pairing is nothing but the Weil pairing.
Using the formula, we develop an X-coordinate only pairing inversion method.
However, the algorithm is still infeasible for cryptographic size problems.